CVE-2026-8190: Wavlink NU516U1 adm.cgi wan os command injection
A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipulation of the argument ppp_username/ppp_passwd/rwan_ip/rwan_mask/rwan_gateway is directly passed by the attacker/so we can control the ppp_username/ppp_passwd/rwan_ip/rwan_mask/rwan_gateway causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8190?
CVE-2026-8190 is classified as a high-severity vulnerability due to its ability to allow OS command injection.
How do I fix CVE-2026-8190?
To fix CVE-2026-8190, you should apply the latest firmware update provided by Wavlink for the NU516U1 M16U1_V240425.
What type of vulnerability is CVE-2026-8190?
CVE-2026-8190 is an OS command injection vulnerability affecting the Wavlink NU516U1's adm.cgi file.
Who is affected by CVE-2026-8190?
The vulnerability CVE-2026-8190 affects users of the Wavlink NU516U1 router running M16U1_V240425 firmware.
What are the potential impacts of CVE-2026-8190?
If exploited, CVE-2026-8190 can lead to unauthorized command execution on the affected Wavlink device.